← Back

CVE-2025-59149

nvd nist
Published: Oct 1, 2025Modified: Oct 6, 2025

JSON object

Loading...
6.2
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.5 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In version 8.0.0, rules using keyword ldap.responses.attribute_type (which is long) with transforms can lead to a stack buffer overflow during Suricata startup or during a rule reload. This issue is fixed in version 8.0.1. To workaround this issue, users can disable rules with ldap.responses.attribute_type and transforms.

Affected (3)

Products: Oisf: Suricata
1 product
Suricata
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Oisf
Version 8.0.0
Version 8.0.0 beta1
Version 8.0.0 rc1

References (4)

Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
Issue TrackingThird Party Advisory
Source: security-advisories@github.com
Issue Tracking

Timeline

No history available yet.